Jobs › Companies › Carter's › Governance, Risk & Compliance Manager (IT)

About this Governance, Risk & Compliance Manager (IT) role at Carter's

Carter's · Onsite · Atlanta, GA

Serving the needs of all families with young children, Carter’s Inc. is the largest North American apparel retailer exclusively for babies and young children, encompassing Carter’s, OshKosh B’gosh, Skip*Hop and Little Planet brands. Meaningful work, constant learning, genuine people, and a community guided by core values that promote inclusion and innovation is in everything we do. There are many reasons to build your career at Carter's.

How you’ll make an impact:


As Carter's accelerates its use of AI technologies — including generative AI assistants, AI-enabled SaaS applications, MCP (Model Context Protocol) connectors, and agentic workflows — this role will ensure that AI adoption is governed with the same rigor applied to any other enterprise technology risk. The Manager will balance traditional IT GRC fundamentals with forward-looking AI governance leadership, making this a uniquely strategic position within the IT organization.

 

AI Governance & Emerging Technology Risk (YR 1 – approx. 60%)

  • Lead the development and implementation of Carter's AI Governance Framework, defining policies for acceptable use, data classification, model risk, vendor AI tools, and agentic workflows aligning with the company’s ERM program.
  • Maintain a comprehensive inventory of AI tools and connectors deployed across the enterprise, including MCP servers, generative AI platforms, and AI-enabled SaaS integrations (e.g., Atlassian, Microsoft 365, Snowflake, Adobe Analytics).
  • Conduct and oversee AI risk assessments covering data exposure (including PII), identify potential vulnerabilities, unauthenticated access risks, and potential risk exposure in MCP connector packages.
  • Define and enforce controls for AI connector permissions, least-privilege access, credential management, and data loss prevention in AI workflows.
  • Monitor the AI regulatory landscape (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001, state AI laws) and translate requirements into actionable controls and policy updates for Carter's.
  • Ensure AI governance aligns with data privacy obligations (e.g., CCPA, COPPA, GDPR) applicable to Carter's customer base, which includes children's products.
  • Provide support to the Carters AI COE team and assist with AI Governance across multiple departments.

 

Compliance & Regulatory Management (40%)

  • Oversee compliance with applicable regulatory frameworks and standards including SOX ITGC, PCI DSS, NIST (Cybersecurity and AI), and CCPA etc.
  • Manage the IT control testing calendar, coordinate evidence collection, and liaise with internal and external auditors throughout audit engagements.
  • Track remediation of audit findings and control deficiencies, providing regular status reporting to the Director of IT GRC and leadership.
  • Support enterprise IT privacy program activities in coordination with the Legal and IT teams, particularly where technology systems process personal data.

 

We’d Love to hear from you if: (Requirements section)


Must have:

  • At Least a bachelor’s degree in a technical field of studies (Mathematics, Computer Science, Accounting, etc.)
  • 7+ years of progressive experience in IT Governance Risk Compliance (GRC), information security, risk management, or a related discipline
  • 7+ years of experience related to building and implementing IT Governance Risk Management programs 
  • 2+ years of direct involvement in AI governance, AI risk assessment, or significant responsibility for AI tool security and compliance.
  • Professional certification (CISSP, CISA, CISM, CGEIT, CRISC, AAIA, AAIR or similar)
  • Strong foundational knowledge of IT GRC frameworks: NIST CSF, NIST AI, ISO 27001, COBIT, SOX ITGC, PCI DSS, and SOC 2.
  • Working knowledge of AI technologies, including generative AI tools, large language models, MCP (Model Context Protocol) server architectures, and agentic AI workflows.
  • Experience assessing AI and SaaS vendor risk, including security questionnaire review, CVE management, and third-party audit evaluation.
  • Understanding data privacy regulations applicable to Carter's: CCPA, CPRA, and GDPR.
  • Proven ability to manage cross-functional programs and influence stakeholders across IT, Legal, Finance, and business without direct authority.
  • Strong written and verbal communication skills; able to translate complex technical risk topics for executive and non-technical audiences.

 

 


Carters is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity, sexual orientation, national origin, genetics, disability, age, veteran status, or any other status protected by federal, state, or local law.

Ready to apply to Carter's?
Apply to Carter's

About Carter's

We’ve become an industry leader by providing quality – from the clothing we sell to the careers we offer our team. Shared values have paved the way to our success. We nurture inclusive work environments for everyone. We invest in our teams with training and development programs to help them build their skills. We succeed together; everyone is welcome to grow in many ways. We’ve kept our close-knit warmth since our founding. You’ll have the opportunity to work with colleagues who often become fast, lifelong friends while making new connections and sharing memorable experiences. Caring, teamwork, flexibility, and growth are what make us different. What’s not to love?

See all jobs at Carter's →

Similar jobs

DP
HR Compliance Manager
DLA Piper
⚡ Apply early Chicago, IL Hybrid $112,879–$165,525
● New 👁 Seen ✓ Applied 2d ago
GP
Payroll Manager (Compliance) - Global Industrial
Genuine Parts Company
⚡ Apply early Birmingham, AL, USA Onsite
● New 👁 Seen ✓ Applied 2d ago
Acrisure
Governance, Risk & Compliance Analyst
Acrisure
⚡ Apply early 999 Peachtree Street Northeast... Onsite
● New 👁 Seen ✓ Applied 1w ago
Procare Solutions
Compliance Manager
Procare Solutions
⚡ Apply early Denver, CO; Atlanta, GA Hybrid $139,400–$150,700
● New 👁 Seen ✓ Applied 1w ago
Elevance Health
Business Change Manager - Third Party Risk & GRC
Elevance Health
⚡ Apply early OH-MASON, 4361 IRWIN SIMPSON R... Hybrid
● New 👁 Seen ✓ Applied 1w ago
The Coca-Cola Company
Manager, IT Governance & Compliance
The Coca-Cola Company
⚡ Apply early US - GA - Atlanta Onsite
● New 👁 Seen ✓ Applied 1w ago
JE
Compliance Manager (P&C Insurance)
Jencap
⚡ Apply early Atlanta, GA Hybrid
● New 👁 Seen ✓ Applied 1w ago
Truist
Compliance Officer- Fair Banking and Regulatory Program
Truist
⚡ Apply early Charlotte, NC Onsite $88,000–$110,000
● New 👁 Seen ✓ Applied 1w ago
Starr Insurance
Regulatory and Compliance Analyst
Starr Insurance
⚡ Apply early 399 Park Avenue-New York, NY Onsite
● New 👁 Seen ✓ Applied 1w ago

Sign up for suggestions tailored to the jobs you open and the searches you save.

More jobs at Carter's

See all jobs at Carter's →

Apply now
🤖

Whoa — hold up

JobsRadar was built for real people having a rough time in their job search — not for automated requests. You're clicking way too fast and you're now temporarily blocked.

Come back later. If you're genuinely job hunting, we've got your back — just act like a human.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Get an edge on your job hunt.

Join our Telegram channel for the stuff that helps you land the role — salary benchmarks, the weekly market pulse, and new-feature drops. No spam, just signal.

Join the channel — it's free